Irony alert: OpenAI whines that Chinese model stole its special IP that it stole from everybody else
US model makers can train on web data - but distilling theirs is a 'national security risk'
OpenAI, a company that amasses large volumes of internet content while facing copyright issues, has accused individuals linked to China's Moonshot AI of engaging in a distillation attack starting July 1. The company warns that extracting reasoning from their models at scale could enable rivals to train capable models without maintaining the same safeguards.
Distillation is a machine learning technique where one model's outputs train another, potentially reproducing reasoning and capabilities. Both governmental and major US AI firms, including Google and Anthropic, have accused Chinese rivals, specifically Moonshot AI, of using distillation to replicate American models' capabilities.
In a blog post on Wednesday, OpenAI reported spotting and disrupting an adversarial distillation campaign that ran throughout July. The operators did not violate encryption, compromise databases, or access stored user conversations directly. Instead, they manipulated model interactions to reproduce protected reasoning in forms visible to the requester in a coordinated, scaled manner that violated OpenAI's terms of service.
The queries began on July 1, with high-volume spikes on July 24 and 25 consisting of 16,000 requests using an extraction pattern from over 4,000 users. OpenAI identified related 'prompt-pattern activity' across more than 15,000 users and fully disrupted the campaign on July 28.
It remains unclear if all operators during the July time period were associated with a single rival AI company, but the core cluster of the theft is attributed to Moonshot AI, developers of Kimi. The Register attempted to contact Moonshot AI for comment without receiving an immediate response. OpenAI also inquired about the targeted models during the July campaign, but did not receive a response.
In late July, US President Donald Trump's Assistant for Science and Technology, Michael Kratsios, accused Moonshot AI of creating its Kimi K3 model by distilling Anthropic's Fable. Anthropic's Claude Opus 5.5 model, released a week ago, includes a defense against distillation called 'preserved thinking,' introduced with Fable 5.1.
OpenAI emphasized that adversarial distillation poses safety and national security risks, as extracted reasoning could be used to train another model without preserving safeguards applied to the original model's user-facing outputs. At scale, distillation can accelerate the transfer of advanced capabilities without requiring the same investment in safety.
The company also noted that concerns heighten as models gain capabilities in dual-use domains. In response, OpenAI banned model-copying accounts, tightened signup and infrastructure controls, expanded monitoring efforts, and closed a pathway that allowed someone possessing another user's encrypted reasoning to replay it and recover its contents.
Additionally, the company worked with service providers to prevent distillation activity from moving to third-party services and shared investigation details with other AI firms through the Frontier Model Forum and government information-sharing programs.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.